CVE-2024-35195

Aliases:GHSA-9wx4-h78v-vm56PYSEC-2026-1873DEBIAN-CVE-2024-35195ALPINE-CVE-2024-35195CGA-2482-gcp4-85fjCGA-2fvw-pqwx-fjv8CGA-33cr-6v3c-467gCGA-3fh7-j6vq-8j3hCGA-3mwf-pfw9-chghCGA-3w6r-fw8f-mw97CGA-447v-v4rh-fmgmCGA-49m3-3jmg-gmjhCGA-4fjw-5hhq-phvfCGA-4g23-7mmm-7c9mCGA-4j4r-hmj6-f5vrCGA-4qgr-p2xc-m523CGA-54v6-q29x-539hCGA-55f3-c8h3-7xmgCGA-56jp-7jrf-xm54CGA-575p-xp64-4pvxCGA-57c8-wf74-xc6wCGA-57qj-wv26-vmv3CGA-5g9x-89cq-3ppgCGA-5jcg-6x22-hqg8CGA-5m3q-jvr8-gwwfCGA-5p9c-w5p5-fg47CGA-68p8-xv99-2gjhCGA-6rv9-m8xh-62xvCGA-72qp-m73m-9jwvCGA-72v4-7x3r-phjvCGA-733q-qqf3-v4wwCGA-73wj-hphq-p52qCGA-774v-wqwh-fpq7CGA-7829-pr63-fj6vCGA-7g3m-5cw7-gp6hCGA-7ph4-qwm7-6m79CGA-7w64-xj89-p3g3CGA-7wp6-m6wr-2pc6CGA-7wx4-9cv3-v22xCGA-89cq-9wpx-4629CGA-8mf5-vg54-4w75CGA-8r8c-f3cw-mv5jCGA-8w9g-64m7-9whwCGA-8wrr-cx9p-24c8CGA-93x7-f52w-97xxCGA-95x3-7265-8wr2CGA-97wh-xjj7-7cg2CGA-9gqv-hp72-63gmCGA-9jjv-32wq-6474CGA-9jmm-6cwf-26gvCGA-9vjp-5vcw-qx5qCGA-9vqh-2q9q-j87rCGA-c382-jh52-65mpCGA-c5xj-7rrp-w68vCGA-cv8m-f96g-xrqxCGA-cwx6-4jx8-rfq3CGA-f53g-rqxq-h6j2CGA-f78p-c28j-4xg7CGA-f86p-fw8p-4m6hCGA-fv95-95qx-24cqCGA-g46p-rh84-qg6fCGA-g93r-w94w-5vr2CGA-gqq2-rcv4-5m89CGA-gv6x-vq3q-c99vCGA-h64g-pwr3-r3r5CGA-h9pp-qp4r-r24hCGA-hffw-24j4-rpw2CGA-hg58-6pqv-jxf6CGA-hjg4-rpc7-7h7vCGA-hp84-hcmw-8p62CGA-hp85-fj9v-j6rcCGA-jh84-rjp3-fv6qCGA-jjm7-w6fp-c4pxCGA-jmfx-m2ch-6gh7CGA-m835-p8h7-jf7vCGA-m8mh-hmw6-mph6CGA-m9h2-jpw6-q84xCGA-m9q7-rgrr-jw43CGA-mf6v-8j35-7f5vCGA-mgc9-r55p-9gqgCGA-mmc3-5f9p-g3c8CGA-mrm4-jcfw-v692CGA-mwhg-r955-4cqfCGA-p22x-mwm2-249rCGA-p4gj-229j-h44xCGA-p6f5-c6vv-rhwqCGA-p93h-m5jp-7v48CGA-p95p-9r29-2xmqCGA-pfx9-3r99-w92jCGA-pwfr-c6rc-r5x4CGA-39gv-m326-rcvrCGA-53pv-wfpx-3mfpCGA-5qxv-8886-2h4vCGA-6wxf-gf29-c7x5CGA-883g-v563-qm82CGA-8mgm-8c6h-c5w4CGA-8pcq-q66h-9wh6CGA-fc7q-cf58-hv94CGA-j9qv-8fff-57mjCGA-mq8v-v37f-9wcjCGA-q5r5-5cx2-wrxcCGA-q7cp-j8j9-xgmrCGA-q923-7rf3-ghqcCGA-qpf6-hh3h-j3w6CGA-qqqj-545x-vw44CGA-qr36-653j-hxc9CGA-qrrv-6fcx-72xgCGA-qwhh-mf25-jcm8CGA-qx69-r68h-vx8gCGA-r43r-vmjf-899xCGA-rg36-p259-787rCGA-rhph-j9m6-rw89CGA-rmg5-8g3j-7jcjCGA-rppf-jq53-fv4cCGA-rq4r-8rc9-w4xjCGA-rv8v-w385-v446CGA-rwxh-6mvh-j38hCGA-v235-hf78-8c2gCGA-v5c3-6fcj-7755CGA-v88q-f9hj-wcr5CGA-vggp-rxq5-8cpgCGA-vvjr-pm7v-vx4wCGA-w548-7mcq-ww23CGA-w9jj-qvm5-7gc3CGA-wgh5-82vr-qg4qCGA-wh7p-vgrh-g28qCGA-wj8c-8hr8-rr3vCGA-wqch-2qw3-r88xCGA-wx2p-x7fc-9hpvCGA-x3xw-7xr4-8jmjCGA-x45j-ghxh-2rjrCGA-xrhw-jmw9-fgqgCGA-xvg2-x255-7jfhCGA-xwgv-69q6-v257
Advisory lineage Upstream: 0 Downstream: 26
Deferred
Published: 20 May 2024, 20:14
Last modified:31 Jul 2025, 03:56

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.6 MEDIUM
v3.1 (cve.org)
EPSS Score
0.34% LOW
0% probability +0.29%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

20 May 2024, 20:14
Published
Vulnerability first disclosed
31 Jul 2025, 03:56
Last Modified
Vulnerability information updated

Description

Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests `Session`, if the first request is made with `verify=False` to disable cert verification, all subsequent requests to the same host will continue to ignore cert verification regardless of changes to the value of `verify`. This behavior will continue for the lifecycle of the connection in the connection pool. This vulnerability is fixed in 2.32.0.

CVSS Metrics

  • v3.1MEDIUMScore: 5.6CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N

EPSS Trends

Current EPSS score: 0.34% Percentile: 28%

Techniques & Countermeasures

  • CWE-670Always-Incorrect Control Flow Implementation

    The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.

Affected Systems

  • alpinepy3-requests

    < 2.32.3-r0 | < 2.32.3-r0 | < 2.32.3-r0 | < 2.32.3-r0 | < 2.32.3-r0 | < 2.32.3-r0 | < 2.32.3-r0

  • chainguardairflow

    < 2.9.1-r1

  • chainguardairflow-bitnami-compat

    < 2.9.1-r1

  • chainguardapache-beam-python-3.11-sdk

    < 2.59.0-r0

  • chainguardaz

    < 2.70.0-r0

  • chainguardaz-iamguarded-compat

    < 2.70.0-r0

  • chainguardcheckov

    < 3.0.34-r1

  • chainguardconfluent-docker-utils

    < 0.0.78-r0

  • chainguardggshield

    < 1.28.0-r1

  • chainguardgraalvm-24-graalpy-venv

    all

  • chainguardjwt-tool

    < 2.2.7-r0

  • chainguardk8s-sidecar

    < 1.27.2-r0

  • chainguardk8s-sidecar-1.22

    < 1.22.4-r2

  • chainguardkatib-controller

    < 0.18.0-r0

  • chainguardkatib-controller-compat

    < 0.18.0-r0

  • chainguardkatib-db-manager

    < 0.18.0-r0

  • chainguardkatib-db-manager-compat

    < 0.18.0-r0

  • chainguardkatib-earlystopping

    < 0.18.0-r0

  • chainguardkatib-file-metricscollector

    < 0.18.0-r0

  • chainguardkatib-file-metricscollector-compat

    < 0.18.0-r0

  • chainguardkatib-suggestion-goptuna

    < 0.18.0-r0

  • chainguardkatib-suggestion-goptuna-compat

    < 0.18.0-r0

  • chainguardkatib-suggestion-hyperband

    < 0.18.0-r0

  • chainguardkatib-suggestion-hyperopt

    < 0.18.0-r0

  • chainguardkatib-suggestion-nas-darts

    < 0.18.0-r0

  • chainguardkatib-suggestion-nas-enas

    < 0.18.0-r0

  • chainguardkatib-suggestion-optuna-enas

    < 0.18.0-r0

  • chainguardkatib-suggestion-pbt-enas

    < 0.18.0-r0

  • chainguardkatib-suggestion-skopt-enas

    < 0.18.0-r0

  • chainguardkatib-tfevent-metricscollector

    < 0.18.0-r0

  • chainguardkubeflow-jupyter-web-app

    < 1.8.0-r7

  • chainguardkubeflow-katib

    < 0.18.0-r0

  • chainguardkubeflow-pipelines

    < 2.2.0-r2

  • chainguardkubeflow-pipelines-apiserver

    < 2.2.0-r2

  • chainguardkubeflow-pipelines-cache_server

    < 2.2.0-r2

  • chainguardkubeflow-pipelines-cache-deployer

    < 2.2.0-r2

  • chainguardkubeflow-pipelines-cache-deployer-compat

    < 2.2.0-r2

  • chainguardkubeflow-pipelines-frontend

    < 2.2.0-r2

  • chainguardkubeflow-pipelines-metadata-envoy-config

    < 2.2.0-r2

  • chainguardkubeflow-pipelines-metadata-writer

    < 2.2.0-r2

  • chainguardkubeflow-pipelines-metadata-writer-compat

    < 2.2.0-r2

  • chainguardkubeflow-pipelines-persistence_agent

    < 2.2.0-r2

  • chainguardkubeflow-pipelines-scheduledworkflow

    < 2.2.0-r2

  • chainguardkubeflow-pipelines-viewer-crd-controller

    < 2.2.0-r2

  • chainguardkubeflow-pipelines-visualization-server

    < 2.3.0-r0

  • chainguardkubeflow-volumes-web-app

    < 1.8.0-r6

  • chainguardmlflow

    < 2.13.1-r0

  • chainguardmlflow-iamguarded-compat

    < 2.13.1-r0

  • chainguardnvidia-nsight-compute-13.1

    < 2025.4.0.12-r0 | < 2025.4.1.2-r1

  • chainguardnvidia-nsight-compute-13.2

    < 2026.1.1.2-r2

Showing first 50 affected entries in server-rendered view.

References (14)